A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmmstateauthentication/emmstateauthentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.
[
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/amf/gmm-sm.c",
"function": "gmm_state_security_mode"
},
"id": "CVE-2025-5520-0ef524c2",
"deprecated": false,
"digest": {
"function_hash": "83500632070580911998797047966065524410",
"length": 8423.0
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/amf/gmm-sm.c",
"function": "gmm_state_exception"
},
"id": "CVE-2025-5520-3a05cf93",
"deprecated": false,
"digest": {
"function_hash": "160781599133266726046446224547111322076",
"length": 7169.0
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/mme/emm-sm.c",
"function": "emm_state_authentication"
},
"id": "CVE-2025-5520-6869893c",
"deprecated": false,
"digest": {
"function_hash": "22859958192396035505212974093563823443",
"length": 4124.0
}
},
{
"signature_type": "Line",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/amf/gmm-sm.c"
},
"id": "CVE-2025-5520-7cf36230",
"deprecated": false,
"digest": {
"line_hashes": [
"162612948853236519870417624286336986397",
"279800737103072097352342639440643898857",
"224344108714082424795084970797513107060",
"92174190948770943019300478285797406489",
"11496801759268304833503557185898646113",
"279800737103072097352342639440643898857",
"63600953943289955141616430274593087484",
"256210522018344380583522769866622864221",
"8531826659309212253945361217639555917",
"279800737103072097352342639440643898857",
"63600953943289955141616430274593087484",
"256210522018344380583522769866622864221",
"88933678767554333444634080757504132882",
"279800737103072097352342639440643898857",
"63600953943289955141616430274593087484",
"98279082891080693496667047401417186958",
"218423668681304689602073986062147818177",
"279800737103072097352342639440643898857",
"63600953943289955141616430274593087484",
"98279082891080693496667047401417186958",
"218423668681304689602073986062147818177",
"287361486533403811949021440182620113055",
"329928212348722115459337753229020731516",
"221167672963450854736231568572233024945",
"171710928360583683359703307818570784637"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/mme/emm-sm.c",
"function": "emm_state_exception"
},
"id": "CVE-2025-5520-8258339c",
"deprecated": false,
"digest": {
"function_hash": "7840338246266733304109947859179352179",
"length": 2198.0
}
},
{
"signature_type": "Line",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/mme/emm-sm.c"
},
"id": "CVE-2025-5520-888aab85",
"deprecated": false,
"digest": {
"line_hashes": [
"181587525657022427075386250389554607630",
"214597673683049392675310664109267682895",
"44783538911283254919575295468980251765",
"17076408781526451615758545393702765642",
"181587525657022427075386250389554607630",
"252775408427670992673771619141331972551",
"258020227633328548922632536403702770528",
"133599961499748681934399517810130714389",
"181587525657022427075386250389554607630",
"193216346956972609628193931368582367486",
"210300223049496830621915461069147382003",
"14486022831773130212852169467389047262",
"181587525657022427075386250389554607630",
"53677434448106881679034576068327455465",
"22640183906031040781591380454654267857",
"135300274118787480034969130986824843604"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/amf/gmm-sm.c",
"function": "common_register_state"
},
"id": "CVE-2025-5520-ad2585fe",
"deprecated": false,
"digest": {
"function_hash": "116882255355674317971163153045468861679",
"length": 9739.0
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/mme/emm-sm.c",
"function": "emm_state_security_mode"
},
"id": "CVE-2025-5520-b03c51d3",
"deprecated": false,
"digest": {
"function_hash": "72387096183728905946385029289657893898",
"length": 5578.0
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/amf/gmm-sm.c",
"function": "gmm_state_initial_context_setup"
},
"id": "CVE-2025-5520-d911ed6c",
"deprecated": false,
"digest": {
"function_hash": "58969063080390576501044478447730453268",
"length": 8629.0
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/amf/gmm-sm.c",
"function": "gmm_state_authentication"
},
"id": "CVE-2025-5520-f9f3436d",
"deprecated": false,
"digest": {
"function_hash": "126460456160147151523067791108123358265",
"length": 8606.0
}
},
{
"signature_type": "Function",
"source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
"signature_version": "v1",
"target": {
"file": "src/mme/emm-sm.c",
"function": "emm_state_initial_context_setup"
},
"id": "CVE-2025-5520-fc955644",
"deprecated": false,
"digest": {
"function_hash": "59366305747887547644834116805621754724",
"length": 5436.0
}
}
]
[
{
"events": [
{
"introduced": "2.7.0"
},
{
"last_affected": "2.7.3"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5520.json"
"2026-04-12T17:14:07Z"